治理、风险与合规专家,GTM - V4G
Governance, Risk, and Compliance Expert, GTM - V4G
在 Vanta,我们的使命是帮助企业在赢得和证明信任方面取得成功。我们相信安全应该持续监控和验证,我们赋能企业实践更好的安全措施,并轻松证明其安全性。Vanta 有一支善良且才华横溢的团队,虽然一些成员有之前的安全经验,但许多人在没有相关经验的情况下也在 Vanta 取得了成功。
作为 Vanta 的 GTM 面向 GRC 专家,支持 Vanta for Government(V4G)机会,你将成为 Vanta 安全团队中一位高度可见、面向客户的领导者,负责向潜在客户和客户展示 Vanta 的 Trust Management Platform,具备深厚的公共部门合规专业知识,涵盖 FedRAMP、GovRAMP、TX-RAMP、NIST 800-53、CMMC 2.0 和 NIST 800-171。你还将与内部团队合作,协助推动和实施新的 V4G 产品功能。该职位主要涉及 Vanta 的售前和营销活动,负责新客户关于 V4G GRC 的对话以及现有客户产品使用扩展,同时通过代表 Vanta 参与公开场合的讨论和演讲来支持营销工作。
如果你觉得这正是你的方向,并且你渴望利用你在安全、隐私以及更广泛的政府导向 GRC 方面的经验来帮助我们增长和销售产品,我们很期待收到你的简历。
在 Vanta 担任治理、风险与合规专家,GTM - V4G 的职责包括:
- 利用你在 FedRAMP、GovRAMP、TX-RAMP、NIST 800-53、CMMC 2.0 和 NIST 800-171 等合规框架方面的专业知识,就范围界定、政策制定、详细控制要求和安全最佳实践等问题为客户提供建议,并推荐与这些框架相关的 Vanta 产品实现方案。
- 与 Vanta 的销售、客户管理及解决方案工程团队合作,主导公共部门 GRC 相关的讨论和活动,向潜在客户和客户展示 Vanta 的 Trust Management Platform。
- 成为 V4G 产品功能的专家,将它们如何优化潜在客户/客户在公共部门的 GRC 流程进行转化。
- 与潜在客户和客户组织的高管和高级员工建立联系,与客户的安全、隐私和 AI 团队建立关系。
- 回答内部和外部利益相关者关于 GRC 计划的问题,包括计划基础/扩展策略、特定框架的要求、第三方风险管理以及更广泛的 IT、安全、
查看英文原文
At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it.
As one of Vanta’s GTM-facing GRC Subject Matter Experts supporting Vanta for Government (V4G) opportunities, you will be a highly visible, customer-facing leader within Vanta’s Security team, responsible for representing Vanta’s Trust Management Platform to prospects and customers, bringing deep public-sector compliance expertise across FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171. You will also have a role in collaborating with internal teams to help drive and implement new V4G product features. This role is specifically involved with Vanta's pre-sales and marketing motions, owning V4G GRC conversations for net-new prospects and the expansion of existing customers' use of the product, as well as supporting marketing efforts by representing Vanta in public-facing conversations and speaking engagements.
If this sounds like you, and you're excited to use your Security, Privacy, and broader Gov-focused GRC experience to help grow and sell our product, we'd love to hear from you.
What you’ll do as a Governance, Risk, and Compliance Expert, GTM - V4G at Vanta:
- Use your expert knowledge of compliance frameworks like FedRAMP, GovRAMP, TX-RAMP, NIST 800-53, CMMC 2.0, and NIST 800-171, to advise customers regarding questions about scoping, policy creation, detailed control requirements and security best practices, and recommend implementations within Vanta’s product related to these frameworks.
- Partner with Vanta's Sales, Account Management, and Solutions Engineering teams and own public-sector GRC discussions & activities, representing Vanta’s Trust Management Platform to prospects/customers.
- Become an expert in V4G product features to translate how they can help optimize prospect/customer public-sector GRC workflows.
- Engage with executives and senior staff at prospect and customer organizations to establish relationships with customer security, privacy, and AI teams.
- Answer questions from internal and external stakeholders on GRC programs, including program foundation/scaling strategies, framework-specific requirements, third-party risk management, and broader IT, security, privacy, and enterprise risk workflows - and how Vanta's platform supports each.
- Develop publicly-available marketing and education content focused on public-sector GRC for prospects, customers, and partners.
- Represent Vanta in public-facing activities including speaking on webinars & panels, participating in conferences, networking at Vanta/partner-led events, and other marketing or thought leadership events.
- Partner with GTM Enablement teams to design and deliver training for Vanta's Sales and Account Management orgs on GRC and Vanta product disciplines across security, privacy, and AI governance.
- Identify customer requirements that expand or improve Vanta’s product across security, privacy, and AI governance, and provide input and feedback for feature development.
- Travel roughly twice per quarter (a few days to a week) for customer onsites, POC workshops, team offsites, and other events.
What we're looking for
- 5+ years of experience US government compliance, with direct experience taking an organization to FedRAMP Ready or Authorized, assessing as a 3PAO, or both.
- Working knowledge of federal frameworks such as FedRAMP (all impact levels and the program's active modernization), CMMC 2.0, NIST 800-53 and 800-171, and StateRAMP/state-program dynamics .
- Foundational knowledge of baseline security compliance frameworks such as ISO 27001 & SOC 2.
- Strong understanding of of SSP and POA&M authorship-level familiarity as well as ConMon operations
- Familiarity with cloud infrastructure, version control systems, risk management, vulnerability management, and their related security processes.
- Experience with third-party/vendor risk management (TPRM) processes, including due diligence, risk scoring, risk assessments, and ongoing monitoring processes.
- Background in broader IT, security, and/or enterprise risk management workflows, including risk scoring, likelihood/impact analysis, and treatment planning.
- Excellent communication and facilitation skills, with the ability to deliver high-impact learning experiences and earn credibility with experienced, senior-level sellers.
- Strong written and verbal communication skills, comfortable engaging customer-facing stakeholders, including C-level contacts, security & privacy leaders, and legal teams, as well as more public partner and industry audiences.
- Comfortable using AI to amplify and strengthen GRC work - demonstrating curiosity, a willingness to learn, and sound judgment in applying AI responsibly to improve efficiency and impact.
- Enterprise sales process literacy (e.g., MEDDPICC) preferred, but not required.
- Customer Trust or Sales Engineering experience preferred, but not required.
- Certifications (e.g., CISA, CISSP, RP, CCA, CCP) and/or formal education preferred, but not required.
What you can expect as a Vanta’n:
- Industry-competitive salary and equity
- Comprehensive medical, dental, and vision coverage, with 100% of employee-only benefit premiums covered for most medical plans
- 16 weeks paid Parental Leave for all new parents
- Health & wellness stipend
- Remote workspace, internet, and cellphone stipend
- Commuter benefits for team members who report to the SF and NYC office
- Family planning benefits
- Matching 401(k) contribution with immediate vesting
- Flexible PTO policy, plus 80 hours of Sick Time
- 11 company-paid holidays
- Virtual team building activities, lunch and learns, and other company-wide events!
- Offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney
To provide greater transparency to candidates, we share base pay ranges for all US-based job postings regardless of state. We set standard base pay ranges for all roles based on function, level, and country location, benchmarked against similar-stage growth companies. Final offer amounts are determined by multiple factors and may vary based on candidate location, skills, depth of work experience, and relevant licenses/credentials.
#LI-remote
At Vanta, we are committed to hiring diverse talent of different backgrounds and as such, it is important to us to provide an inclusive work environment for all. We do not discriminate on the basis of race, gender identity, age, religion, sexual orientation, veteran or disability status, or any other protected class. As an equal opportunity employer, we encourage and welcome people of all backgrounds to apply.
About Vanta
We started in 2018, in the wake of several high-profile data breaches. Online security was only becoming more important, but we knew firsthand how hard it could be for fast-growing companies to invest the time and manpower it takes to build a solid security foundation. Vanta was inspired by a vision to restore trust in internet businesses by enabling companies to improve and prove their security. From our early days automating security monitoring for compliance standards like SOC 2, HIPAA and ISO 27001 to creating the world's leading Trust Management Platform, our vision remains unchanged.
Now more than ever, making security continuous—not just a point-in-time check— is essential. Thousands of companies rely on Vanta to build, maintain and demonstrate their trust— all in a way that's real-time and transparent.
Referral Instructions
If you are being referred for the role, please contact that person to apply on your behalf.